S0205RS3-T07-S0205-Z · Full risk code

Data Persisting in Models Beyond Retention Limits

保留期限屆滿後仍存於模型

Retirement
Risk Description

When an organization deletes source data as required once the retention period expires, but the existing model continues operating and reflecting that data's characteristics; due to unmitigated control gaps, asked during an audit how it ensures expired data is no longer used, the organization has no workable technical answer, triggering compliance exposure and operational reputational costs.

Framework Mappings

EU AI ActArt.10
NIST AI 600-1Data Privacy
ISO/IEC 42001Annex A.7.2、A.7.6
ISO/IEC 5338退役
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Bring models into data lifecycle management so retention policies cover models trained on the data and their derivatives; Before expiry, assess disposition—retraining with exclusion, unlearning, or retirement—and document the rationale; Maintain a data-to-model register so audits can trace which models each batch influenced